- Microsoft security solutions is the largest domain at 35-40%, so it deserves your first study block.
- Passing requires a scaled score of 700/1000, not a fixed 70% raw-correct threshold.
- Testing time is 45 minutes inside a 65-minute scheduled appointment - budget accordingly.
- No prior certification, degree, or training hours are required; only Azure/Microsoft 365 familiarity is recommended.
What SC-900 Actually Tests
Microsoft Certified: Security, Compliance, and Identity Fundamentals - the SC-900 exam - is designed to confirm that a candidate understands the foundational concepts behind Microsoft's security, compliance, and identity product families, without requiring hands-on administrative experience. It is not a deep technical exam; it's a conceptual one. If you've spent any time reading about how to pass difficult Microsoft exams, you already know that Fundamentals-level exams reward breadth of understanding over depth of configuration skill, and SC-900 is a textbook example of that pattern.
Before diving into domain specifics, it helps to understand exactly what this credential is and isn't. If you're still forming a mental model of the exam, our overview on what SC-900 is and the related explainer on SC-900 meaning are useful starting points. For a plain-language answer to what SC-900 stands for, that article breaks down each letter and number in the naming convention Microsoft uses across its role-based tracks.
Registration and Exam-Day Mechanics
SC-900 is delivered as a proctored, computer-based exam through Pearson VUE, with Certiport also listed as an option for students and educators. The official U.S. checkout fee is not consistently published by Microsoft at the time of writing; a commonly cited third-party reference figure is US$99, but you should treat that as unverified until you see the number confirmed at checkout, since regional taxes and occasional discount vouchers can change the total. There is no member versus non-member pricing structure to worry about. For a fuller breakdown of what affects your final price, see our dedicated piece on SC-900 certification cost.
On exam day, the standard appointment window is 65 minutes, but the actual testing time allotted for answering questions is 45 minutes - the difference covers check-in, the NDA agreement, and a post-exam survey. Microsoft does not disclose the exact number of scored versus unscored items for SC-900 specifically. Exams across the broader Microsoft catalog typically fall somewhere in the 40-60 question range, but that is a general pattern, not a guarantee for this exam. Interactive item types are possible during a proctored session, though the exact mix of formats isn't publicly detailed.
There's also no in-exam access to Microsoft Learn documentation, so anything you'd normally look up on the job needs to be memorized or reasoned through independently during the test. Remote delivery is available where supported by your testing region. For scheduling logistics, including how far in advance to book, check SC-900 exam dates.
Key Takeaway
Plan your appointment assuming 45 minutes of active question time - pace yourself so you're not rushing through the compliance domain because you lingered too long on identity scenarios.
Domain-by-Domain Breakdown
SC-900 is organized into four domains, and the weighting tells you exactly where to spend your energy. A full breakdown of each area, including sub-topics and typical phrasing patterns, is available in our companion resource, SC-900 Exam Domains 2026: Complete Guide to All 4 Content Areas. Here's the condensed version for planning purposes.
Domain 1: Describe the concepts of security, compliance, and identity (10-15%)
This is the smallest domain but the conceptual foundation everything else builds on.
- Shared responsibility model and defense in depth
- Zero Trust principles and the CIA triad
- Basic encryption, hashing, and governance risk compliance (GRC) vocabulary
Domain 2: Describe the capabilities of Microsoft Entra (25-30%)
This domain covers identity and access management concepts across Microsoft's identity platform.
- Authentication methods, MFA, and Conditional Access logic
- Identity types: cloud, hybrid, and external/guest identities
- Access reviews, entitlement management, and Privileged Identity Management concepts
Domain 3: Describe the capabilities of Microsoft security solutions (35-40%)
This is the largest domain on the exam, and it deserves the most study time by a wide margin.
- Microsoft Defender family (Endpoint, Office 365, Identity, Cloud Apps)
- Microsoft Sentinel and security information/event concepts
- Cloud security posture management and extended detection and response (XDR) fundamentals
Domain 4: Describe the capabilities of Microsoft compliance solutions (20-25%)
This domain focuses on governance, data protection, and regulatory tooling.
- Microsoft Purview: data loss prevention, information protection, insider risk
- Compliance Manager and compliance score concepts
- Records management, eDiscovery, and audit capabilities
Because Domain 3 alone represents more than a third of the exam, it's worth reviewing our detailed piece on the topic, and cross-referencing your notes against the SC-900 Cheat Sheet once you've covered the material once, so you can confirm you haven't skipped any subtopic that's frequently tested.
| Domain | Weight | Study Priority |
|---|---|---|
| Microsoft security solutions | 35-40% | Highest - study first, review last |
| Microsoft Entra | 25-30% | High - second priority |
| Microsoft compliance solutions | 20-25% | Moderate - dedicate a focused week |
| Security, compliance, and identity concepts | 10-15% | Foundational - cover early, revisit briefly |
Question Style and Format
SC-900 is a Fundamentals-level exam, so most questions test recognition and conceptual matching rather than multi-step troubleshooting. Expect scenario-based multiple choice, drag-and-drop matching of terms to definitions, and "select all that apply" style items describing a capability and asking which Microsoft product delivers it. Because the exact scored item count and type distribution aren't publicly disclosed by Microsoft, don't over-index on any single practice source's claimed format - instead, get comfortable recognizing terminology quickly, since speed matters within the 45-minute window.
The passing score is 700 out of a scaled 1000-point range. This is a scaled score, not a literal 70% raw-correct requirement - some questions may be weighted differently, and the scaling formula isn't published. For a full explanation of how scaled scoring works and what it means for how many questions you can afford to miss, see SC-900 Passing Score 2026: Exactly What You Need to Pass.
A Domain-Weighted Study Timeline
A generic weekly study template won't help you much here - what matters is allocating time proportional to domain weight. Here's a four-week structure built specifically around SC-900's own domain percentages, assuming a part-time study schedule.
Foundations + Entra Basics
- Cover Domain 1 concepts: Zero Trust, shared responsibility, encryption basics
- Begin Microsoft Entra: authentication methods and identity types
- Build a glossary of terms you don't immediately recognize
Finish Entra, Start Security Solutions
- Complete Conditional Access, PIM, and entitlement management topics
- Begin Microsoft Defender family products and use cases
- Take a short practice set focused only on Domains 1-2
Deep Dive on Microsoft Security Solutions
- Spend the most hours here since this domain is 35-40% of the exam
- Cover Microsoft Sentinel, XDR concepts, and cloud security posture management
- Re-test yourself on any Defender product you keep confusing with another
Compliance + Full Review
- Cover Microsoft Purview, Compliance Manager, and eDiscovery basics
- Run two full-length timed practice exams under 45-minute conditions
- Review missed items against the domain list, not just the raw score
If you want to gauge realistically how much total effort this timeline represents for your background, our guide on how hard the SC-900 exam actually is puts the difficulty in context relative to other entry-level credentials.
Common First-Attempt Mistakes
Most candidates who don't pass on the first try aren't failing because the material is inherently difficult - they're failing because they misjudge where the exam's weight actually sits. Here are the patterns worth avoiding.
- Under-studying the largest domain. Because Microsoft security solutions makes up 35-40% of the exam, spending equal time across all four domains guarantees you're under-prepared for the section that matters most.
- Confusing similarly named Defender products. Defender for Endpoint, Defender for Office 365, Defender for Identity, and Defender for Cloud Apps each protect different surfaces - mixing them up is one of the most common error patterns.
- Treating "passing score" as a percentage. The 700/1000 scaled score doesn't map directly to 70% raw correct answers, so don't assume you can skip a section and still comfortably clear the bar.
- Assuming prerequisites exist. There's no required degree, prior certification, or minimum training hours - but skipping basic Azure and Microsoft 365 familiarity tends to slow candidates down on scenario questions. Full detail is in SC-900 Requirements 2026.
- Not practicing under time pressure. With only 45 minutes of testing time, candidates who never rehearse a timed set often run out of time on the compliance domain questions near the end.
Key Takeaway
Run at least one full timed practice session before exam day using resources like our practice test platform so the 45-minute pace feels familiar rather than stressful.
Who Actually Hires for SC-900
SC-900 sits at the entry point of Microsoft's security, compliance, and identity certification track. It's commonly pursued by early-career IT staff, help desk and support technicians moving toward security-focused roles, compliance and governance professionals who need Microsoft-specific vocabulary, and non-technical stakeholders - like project managers or auditors - who work alongside security teams and need to understand the terminology without configuring systems themselves. Because it validates conceptual literacy rather than deep technical skill, it's frequently used as a stepping stone toward more advanced role-based Microsoft credentials.
If you're weighing whether the credential is worth pursuing given your career stage, our analysis on whether SC-900 certification is worth it covers the trade-offs in more depth, and the companion piece on SC-900 Jobs outlines the kinds of roles where this credential tends to appear on job postings or internal skill matrices. For those curious about how the certification could factor into compensation conversations, see SC-900 Salary Guide 2026 - treat any figures there as qualitative context rather than guarantees, since compensation depends heavily on role, region, and experience.
One advantage worth noting for planning purposes: this is a Fundamentals-level credential, and it does not expire. There's no renewal assessment or continuing-education requirement to schedule later, which makes it a low-maintenance addition to a resume once earned.
For a broader library of related explainers - including deep dives on what a SC-900 is, what SC-900 means, and what SC-900 certification involves - along with structured SC-900 training resources and the core SC-900 Certification overview, our blog maintains a full set of companion articles. Pairing that reading with timed practice on our SC-900 practice test platform is the most efficient way to convert study time into exam-day confidence.
FAQ
It's designed as an entry-level Fundamentals exam, so no prior certification or technical degree is required. Azure and Microsoft 365 familiarity is recommended, and reviewing all four domains - especially the heavily weighted Microsoft security solutions domain - closes most knowledge gaps.
The scheduled appointment is 65 minutes total, but the actual testing time for answering questions is 45 minutes. The remainder covers check-in and post-exam formalities.
You need 700 out of a scaled 1000-point range. This is not the same as needing 70% of raw questions correct, since the scoring is scaled rather than a direct percentage.
Start with Domain 1 (concepts) to build vocabulary, then prioritize Domain 3, Microsoft security solutions, since it represents 35-40% of the exam - the largest single content area.
No. As a Fundamentals-level credential, SC-900 does not expire and has no renewal assessment or continuing-education requirement.